ID token

In OpenID Connect, the signed JSON Web Token that tells the client application who the user is and when and how they authenticated at the OpenID provider.

The ID token is what OpenID Connect adds to OAuth 2.0 to carry authentication: the OpenID provider issues it to the client application, the relying party. OpenID Connect Core 1.0 specifies it as a JSON Web Token signed by the provider. Its claims state who issued it, which user it describes, which client it is for, when it was issued and when it expires, and can record when and how the user authenticated. NIST SP 800-63C-4 names the ID token as an example of an assertion, like a SAML assertion.

It is often confused with the access token. The ID token is for the client: it says who signed in, and the client validates its signature, issuer, audience and expiry before trusting it. The access token is for the API, the resource server: it authorises calls and is commonly opaque to the client. Treating an access token as proof of login is a known misuse that the ID token is meant to replace.

Exam relevance: a scenario is likely to ask which token tells an application who the user is, or what OpenID Connect adds to OAuth. Candidates are expected to answer the ID token for identity and the access token for API authorisation, and to remember that OAuth alone delegates access rather than authenticating the user.